US10171289B2

Event and alert analysis in a distributed processing system

Summary by NHIP

Distributed event alert analysis

The method receives events from a queue and creates temporary alerts using local rules within an embedded analyzer. The alert analyzer subsequently processes these temporary alerts alongside alerts generated by multiple external event analyzers based on their own rules.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

Methods, apparatuses, and computer program products for event and alert analysis are provided. Embodiments include a local event analyzer embedded in an alert analyzer receiving events from an event queue. Embodiments also include the local event analyzer creating, based on the received events and local event analysis rules specific to the alert analyzer, a temporary alert for the alert analyzer. Embodiments also include the alert analyzer analyzing the temporary alert based on alert analysis rules.

US10171289B2, drawing sheet 1
Sheet 1 of 10

Term

7.8 yearsleft in the term

Expires 16 July 2034, including 308 days of term adjustment.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

6 claims: 1 independent, 5 dependent

  1. 1
    Broadest claimClaim Score 44, average(NHIP)A method of event and alert analysis in a distributed processing system, the distributed processing system including a local event analyzer embedded in an alert analyzer, the method comprising:receiving, by the local event analyzer embedded in the alert analyzer, events from an event queue;creating, based on the received events and local event analysis rules specific to the alert analyzer, by the local event analyzer, a temporary alert for the alert analyzer, wherein the temporary alert is an alert that is visible to one or more specific alert analyzers including the alert analyzer;receiving, by the alert analyzer, alerts created by a plurality of event analyzers, wherein each event analyzer of the plurality of event analyzers is configured to create the alerts by processing the events from the event queue according to each event analyzer's own event analysis rules;and analyzing, by the alert analyzer, based on alert analysis rules, the temporary alert and the alerts created by the plurality of event analyzers.